PSD3 fraud prevention: what Irish payment firms need to know

The transition from PSD2 to PSD3 represents a significant evolution in the EU payments framework, with fraud prevention emerging as a key area of regulatory focus.

This deep dive is the third in the line of our PSD3 and PSR series – review part 1: Wind-down planning under PSD3 and part 2: PSD3 licensing changes. While PSD2 introduced Strong Customer Authentication (SCA) to reduce unauthorised payment fraud, PSD3 goes further by expanding requirements around payment verification, transaction monitoring and fraud liability.

These changes, which will largely be implemented through the new Payment Services Regulation (PSR), are intended to create a more consistent approach to fraud prevention across the European Union while strengthening consumer protection.

For Irish payment institutions and e-money firms, the proposed framework will require more than incremental compliance changes. Firms will need to reassess their fraud risk management frameworks, enhance monitoring capabilities and prepare for increased accountability where fraud losses occur.

A broader view of fraud

Under PSD3, the concept of fraud extends beyond unauthorised transactions to include a growing range of Authorised Push Payment (APP) type scams.

In these scenarios, customers authorise payments themselves but do so as a result of deception or manipulation by fraudsters. Common examples include:

  • Impersonation scams, where fraudsters pose as banks, regulators or service providers
  • Invoice redirection fraud, where payment details are altered before settlement
  • Social engineering attacks designed to influence customers into making payments

As fraud tactics continue to evolve, regulators are placing greater emphasis on preventative controls and early intervention measures.

Verification of payee: strengthening payment security

One of the most significant changes under PSD3 is the introduction of Verification of Payee (VoP) requirements.

Before a payment is executed, firms will be required to verify that the beneficiary's name matches the account details provided by the payer. The objective is to reduce misdirected payments and help prevent APP fraud by identifying discrepancies before funds leave the customer's account.

For many firms, this may require substantial enhancements to existing payment infrastructure and customer journeys.

Key considerations include:

  • Upgrading systems to support real-time verification checks
  • Integrating VoP controls seamlessly into payment processes
  • Establishing clear exception and escalation procedures for mismatches

Early planning will be critical, particularly for firms that currently lack the technology infrastructure needed to support real-time verification.

Increased liability for fraud losses

PSD3 also signals a shift in regulatory expectations regarding responsibility for fraud losses.

The proposed PSR expands customer protection in certain fraud scenarios, including impersonation fraud, and increases expectations on PSPs to implement effective fraud prevention controls. Firms should closely monitor the final legislative outcome to assess the extent of any reimbursement obligations. As a result, firms are likely to face greater financial and operational exposure where fraud prevention measures are deemed insufficient.

To prepare, firms should consider:

  • Conducting detailed assessments of the new liability provisions
  • Reviewing customer reimbursement and dispute resolution processes
  • Strengthening escalation, investigation and incident management procedures
  • Ensuring fraud risk is appropriately reflected within enterprise risk management frameworks

Understanding the financial implications of these changes will be essential as firms assess their future risk appetite and control environment.

Enhanced monitoring and fraud intelligence

PSD3 places increased emphasis on proactive fraud detection through enhanced monitoring and information sharing.

Regulators expect firms to adopt more sophisticated approaches to transaction monitoring, leveraging behavioural analytics and emerging technologies to identify suspicious activity in real time. The framework places greater emphasis on effective transaction monitoring and fraud detection, which may encourage firms to deploy advanced analytics and AI-enabled solutions.

In practical terms, firms should focus on:

  • Enhancing real-time transaction monitoring capabilities
  • Participating in industry fraud intelligence and information-sharing initiatives
  • Assessing emerging technologies, including AI-driven fraud detection solutions

As fraud threats become increasingly complex, effective prevention will depend on an organisation's ability to combine data, technology and governance.

How Forvis Mazars can help

As the PSD3 framework continues to develop, firms will need to assess the impact of new fraud prevention requirements alongside increasing supervisory expectations from regulators such as the Central Bank of Ireland.

Our prudential risk specialists support payment and e-money institutions in evaluating existing fraud prevention frameworks, identifying gaps against emerging regulatory requirements and designing practical remediation programmes. We help firms strengthen governance, risk management and control arrangements to ensure they remain proportionate, effective and capable of standing up to regulatory scrutiny.

Contact